-
Notifications
You must be signed in to change notification settings - Fork 531
chore: production deploy #6874
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+38,845
−14,375
Merged
chore: production deploy #6874
Changes from all commits
Commits
Show all changes
71 commits
Select commit
Hold shift + click to select a range
6e98622
fix(cli): declare the @libpg-query/parser import plpgsql-deparser lea…
spydon e836519
fix(stack): clean up stacks when Docker is unavailable on start and d…
Prashansa-K b8026df
fix(stack): require passwords on the native database socket (CLI-2503…
7ttp 643d648
fix(stack): start auth with zero session limits (CLI-2506) (#6848)
7ttp e29a712
fix(stack): upgrade edge-runtime to v1.77.1 (#6844)
jgoux f5c0a5d
chore(api): sync Management API OpenAPI spec (#6826)
supabase-cli-releaser[bot] f70cda5
fix(cli): read request bodies before local functions respond (#6830)
jgoux e03ea7c
fix(stack): stop Postgres containers with a fast shutdown (#6834)
jgoux 257bee9
perf(cli): initialize catalog schemas without temporary servers (#6831)
jgoux 2c006dd
fix(stack): harden readiness, port claims, and container storage (#6835)
jgoux d4826ec
refactor(stack): flatten the owner process layers (#6836)
jgoux 97c71e7
refactor(stack): unify the database snapshot protocol across engines …
jgoux d021886
feat(cli): drive gen types languages from the @supabase/typegen regis…
spydon dfc52e6
feat(stack): lease owners with a lock and bind session stacks to crea…
jgoux 7cd1a79
feat(stack): ship the functions bootstrap with the package (#6839)
jgoux 1ef5bc0
fix(cli): prefer Docker, then Podman, for automatic stack runtime sel…
jgoux 8e48a07
refactor(stack): own composition policy and stack lookup in the packa…
jgoux afe855a
ci(release): upload release assets one at a time with retries (CLI-24…
kanadgupta b55d919
refactor(cli): cover all `commands` with effect lint (CLI-2408) (#6849)
7ttp a883019
fix(stack): connect Studio to the database and restore its settings (…
avallete 315dbcd
fix(stack): name containers by project and service (#6867)
avallete 7894283
feat(stack): add a testing entrypoint and derive the Promise API (#6841)
jgoux 2547ce5
fix(stack): group database helper containers with their stack (#6870)
avallete 66e92c7
fix(stack): keep Studio awake for 5 minutes after its last request (#…
avallete ff14e91
fix(stack): reduce native stack friction in agent sandboxes (#6856)
avallete 04b1ce9
fix(cli): label non-stable builds in the root help description (#6868)
kanadgupta 8bc13e0
test(stack): wait for the detached owner to exit before removing its …
jgoux 6ea2248
chore: bump pnpm/bun/node, various cleanups (#6806)
kanadgupta ed05cb8
fix(stack): retry image pulls after transient registry failures (#6879)
jgoux 2124262
test(cli): connect live db assertions over TLS (#6843)
avallete 5abfa7d
ci(cli): cache pnpm lockfile verification and drop the Linux stack-po…
kanadgupta c7c9f12
refactor(cli): cover `shared/telemetry` identity and consent with eff…
7ttp 9001c3a
refactor(cli): cover `shared/telemetry` posthog transport with effect…
7ttp 7fa68d3
refactor(cli): cover `shared/telemetry` tests with effect lint (CLI-2…
7ttp 7ececb6
refactor(cli): cover `shared/config` and `shared/auth` with effect li…
7ttp 98cda96
fix(stack): keep in-progress artifact extractions safe from the lefto…
jgoux d38ccd7
test(repo): replace real-time waits in slow CLI and stack tests (#6862)
jgoux 621768f
fix(stack): release log followers on exit (CLI-2521) (#6861)
7ttp f6d5078
refactor(cli): cover `shared/runtime` with effect lint (CLI-2519) (#6…
7ttp e49b791
fix(stack): keep in-use cached artifacts when a request needs more pa…
jgoux 72b10f8
fix(cli): keep migra session settings on reconnect (CLI-2522) (#6884)
7ttp 2a66b74
ci(repo): rebalance slow test jobs and raise integration workers (#6863)
jgoux 288edc2
fix(cli): show stack connection details on start and status (CLI-2546…
avallete 80dc4e0
ci(repo): move the AI review pipeline to gpt-6.1-sol (#6899)
Coly010 5800d06
test(repo): fix windows and live e2e flakes (#6895)
7ttp a1be13e
fix(stack): open a fresh upstream connection per proxied request (#6897)
jgoux b56c765
refactor(cli): cover `shared/git` and `shared/issue` with effect lint…
7ttp 63a2ff5
fix(cli): state stack destroy --yes instead of self-answering prompt …
avallete 6ef3315
test(cli): make reset and stack start integration tests pass on Windo…
avallete 2d7609d
fix(cli): treat the stack database --db-url as local (#6904)
avallete 4371ed3
fix(stack): load function deno.json files as Deno config (#6907)
avallete b8fae81
fix(cli): tidy stack start and non-TTY output friction (#6889)
avallete 87d9efb
fix(stack): reach stack services from Windows and Docker Desktop cont…
avallete 48cabe3
feat(cli): graduate OrioleDB configuration from experimental (#6828)
jgoux 8ae22bc
feat(stack): serve Studio's MCP server at /mcp on the API listener (C…
jgoux 8a7963e
feat(cli): upgrade pg-delta to 1.0.0-alpha.56 (#6913)
avallete 2799c9f
refactor(cli): cover `/shared` init, feedback and services with effec…
7ttp eb0c3ff
fix(config): ignore unset sms provider (CLI-2463) (#6685)
7ttp 233d145
fix(cli): stop splitting escape strings on escaped quotes (CLI-2537) …
7ttp b202ba6
refactor(cli): cover `shared/output` with effect lint (CLI-2561) (#6912)
7ttp 26dc09a
feat(cli): report stack MCP at the API URL and include connection env…
jgoux b29e743
fix(cli): decline unrecognised yes/no prompt answers (CLI-2524) (#6910)
7ttp c877778
fix(cli): reject `test new` names that escape supabase/tests (CLI-248…
7ttp 2b13026
fix(stack): give each Mailpit instance its own database (#6901)
jgoux bb809cf
chore(stack): log lazy wakes instead of bounding them in the proxy (#…
jgoux 3704383
fix(cli): skip the contrib_regression clone on pg-delta shadows (#6920)
avallete a0711c0
fix(stack): keep Storage uploads working on Docker Desktop for macOS …
avallete 481cb3f
fix(stack): serve Storage S3 and resumable uploads behind the gateway…
avallete 62aac0f
feat(stack): pin slim artifacts by revision and make the catalog the …
jgoux 985e0ae
fix(stack): reuse keep-alive upstream connections in the HTTP gateway…
avallete 3cb948c
chore(api): sync Management API OpenAPI spec (#6880)
supabase-cli-releaser[bot] File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1 @@ | ||
| 1.4.1 | ||
| 1.4.2 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 Severity: MEDIUM
The verification cache key contains no dependency-firewall policy or registry revision and has no expiry. A prior positive
lockfile-verified.jsonlcan therefore be reused after a dependency is newly blocked or its registry verdict changes, allowing it to pass the install gate in CI and release builds.Helpful? Add 👍 / 👎
💡 Fix Suggestion
Suggestion: The verification cache key must be made invalidatable when firewall policy or registry verdicts change, independent of lockfile content. Two complementary approaches are recommended:
Add a
verify-cache-versioninput (recommended): In theinputs:section of action.yml, add a new input such asverify-cache-versionwith a default of"1"and a description explaining it should be bumped when the Dependency Firewall policy changes. Then incorporate it into the cache key at line 76, e.g.:key: pnpm-verify-v${{ inputs.verify-cache-version }}-${{ runner.os }}-${{ inputs.dependency-firewall-token != '' && 'firewall' || 'public' }}-${{ hashFiles('pnpm-lock.yaml', 'pnpm-workspace.yaml') }}. Callers bump the version via workflow dispatch or config change whenever a new firewall policy is deployed.Add a weekly date component: Insert a step before the 'Configure pnpm verification cache' step that emits the current ISO year+week number (e.g.,
echo "week=$(date -u +%Y%W)" >> "$GITHUB_OUTPUT") and reference it in the key:...-${{ steps.week.outputs.week }}-${{ hashFiles(...) }}. This guarantees verdicts are re-queried at least once a week even if lockfiles do not change, bounding the window during which a newly-blocked or re-scored dependency can slip through on a stale cached verdict.Both changes require modifying a location other than line 76: Option 1 requires adding a new entry in the
inputs:block (lines 5–21) and then referencing it in the key; Option 2 requires inserting a new shell step before line 74.